CyberRota Analysis
AI-GeneratedNginx Ignition versions prior to 2.41.1 are vulnerable to a flaw that allows remote unauthenticated attackers to create administrator accounts by exploiting a race condition in the onboarding process. This vulnerability can lead to unauthorized access with full ReadWrite permissions, posing a significant risk to the integrity and security of the web server. Organizations using affected versions should prioritize upgrading to 2.41.1 or later to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, with no atomic guard, a remote unauthenticated attacker who can reach an instance in its pre-onboarding state can create an administrator account for themselves — and concurrent requests can create multiple admin accounts in a single race. Version 2.41.1 patches the issue.